PIM/PAM Engineer @ Mumbai

Quess IT Staffing

Mumbai

On-site

INR 1,200,000 - 1,800,000

Full time

15 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Quess IT Staffing is seeking an L2 PAM/PIM Engineer to administer enterprise PAM platforms, onboard targets, and troubleshoot incidents. Role focuses on enforcing zero-trust and least privilege across CyberArk, BeyondTrust, and Microsoft Entra PIM environments.

The candidate will validate controls, rotate credentials, and manage JIT access while coordinating with L3 teams for complex outages and audits. Mumbai-based on-site role with exposure to CIS, ISO 27001, and SOC 2 compliance.

Qualifications

  • Hands-on experience with enterprise PAM tools (CyberArk, BeyondTrust, Delinea/Thycotic) and PIM.
  • Strong understanding of privileged access management concepts and zero-trust.
  • Familiarity with Windows Server AD, Kerberos, GPOs and Linux SSH is desirable.
  • Basic scripting skills to assist with onboarding, discovery, and automation.

Responsibilities

  • Handle day-to-day PAM operations, onboarding, and incident troubleshooting.
  • Validate and audit technical controls to enforce zero-trust and least privilege.
  • Monitor PAM services health and coordinate with support teams for outages.
  • Configure policies, plugins, and connection components within PAM platforms.
  • Perform discovery scans to identify unmanaged privileged accounts and shadow admins.

Skills

CyberArk PAS/Privilege Cloud
BeyondTrust Password Safe
Delinea/Thycotic
Microsoft Entra ID PIM
Windows Server / AD / Kerberos

Job description

The L2 PIM/PAM Engineer is responsible for day-to-day administration, onboarding, and incident troubleshooting across enterprise Privileged Access Management platforms (e.g., CyberArk, BeyondTrust, Microsoft Entra PIM). In addition to operational maintenance, this role actively validates, audits, and assesses technical controls to ensure privileged accounts adhere to strict zero-trust and least-privilege standards.

Key Responsibilities
Implementation & Support (L2 Operations)
  • Handle Day-2 operations, ticket escalations, and incident resolution for PAM components (Safe management, account onboarding, CPM/PSM failures, and policy errors).
  • Onboard target systems (Windows, Linux, databases, network devices, and cloud infrastructure) into PAM vaults with automated credential rotation.
  • Manage Just-In-Time (JIT) access requests, time-bound approvals, and role-activation workflows in Microsoft Entra PIM and PAM solutions.
  • Monitor health checks for core PAM services (Vaults, Proxies, Discovery agents, Session Recording servers) and coordinate with vendor support or L3 teams for complex outages.
  • Configure, test, and maintain custom plugins, CPM platform management policies, and connection components.
Technical Controls Assessment & Validation
  • Conduct routine technical assessments to verify that credential auto-rotation, check-in/check-out policies, and password complexity controls function across all onboarded targets.
  • Validate that Privileged Session Monitoring (PSM) and keylogging controls capture and index administrative sessions without bypassing.
  • Audit Entra PIM policies: verify mandatory MFA triggers, justification requirements, approval chains, and maximum activation duration limits.
  • Perform discovery scans to identify unmanaged privileged accounts, service accounts, and shadow admins across Active Directory, cloud, and hybrid environments.
  • Generate compliance evidence and remediate gaps aligned with audit standards (CIS Benchmarks, ISO 27001, SOC 2).
Required Skills & Qualifications
  • Core Platforms: Hands-on experience with at least one enterprise PAM tool (CyberArk PAS/Privilege Cloud, BeyondTrust Password Safe, Delinea/Thycotic) and Cloud PIM (Microsoft Entra ID PIM).
  • Operating Systems & Networking: Working knowledge of Windows Server (Active Directory, Kerberos, GPOs), Linux/Unix (SSH, PAM modules, sudoers), and networking fundamentals (firewall ports, DNS, RDP, SSH).
  • Scripting: Basic PowerShell, Bash, or Python scripting skills to assist with automated onboarding, discovery parsing, and API calls.
  • Security Principles: Solid understanding of Least Privilege, Zero Trust, MFA, Session Isolation, and Break-Glass procedures.
Preferred Certifications
  • CyberArk Defender (PAM-DEF) or Sentry (PAM-SEN)
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CS PAM Analyst- Hyderabad
CS PAM Analyst- Hyderabad

Cloudxtreme • Hyderabad

Hybrid
INR 800,000 - 1,500,000
PAM Security Engineer
PAM Security Engineer

OP • Bengaluru

On-site
INR 1,500,000 - 2,300,000
BeyondTrust PAM Consultant - C2H
BeyondTrust PAM Consultant - C2H

Orcapod Consulting Services • Hyderabad, Chennai District, Bengaluru

On-site
INR 1,400,000 - 2,100,000
Hybrid work model
CyberArk SME L3 Engineer IAM, IGA & PAM
CyberArk SME L3 Engineer IAM, IGA & PAM

UST • Bengaluru

On-site
INR 3,500,000 - 6,000,000
CyberArk Engineer – PAM, Vault, PVWA, CPM, PSM, PowerShell
CyberArk Engineer – PAM, Vault, PVWA, CPM, PSM, PowerShell

Jobtailor • Gurugram District

On-site
INR 1,200,000 - 2,000,000
Cyber Security Consultant
Cyber Security Consultant

Tata Consultancy Services • Bengaluru

On-site
INR 1,600,000 - 2,100,000
Cyberark Admin
Cyberark Admin

Tata Consultancy Services • Mumbai

On-site
INR 2,500,000 - 3,500,000
Engineering-L2-Bengaluru-Vice President-Security Engineering
Engineering-L2-Bengaluru-Vice President-Security Engineering

Goldman Sachs • Bengaluru

On-site
INR 2,600,000 - 4,200,000
CyberArk Security Engineer
CyberArk Security Engineer

Delta Tech Hub • Bengaluru

On-site
INR 1,200,000 - 2,000,000
PAM Automation Engineer - Remote - Contract opportunity
PAM Automation Engineer - Remote - Contract opportunity

World Wide Technology • India

On-site
INR 1,200,000 - 2,000,000